IP Library Granted Patent US 9,258,287
Granted Patent B2
US 9,258,287 · App. 13/723,036 · Granted Feb 9, 2016

Secure active networks

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,258,287
App. No.
13/723,036
Granted
Feb 9, 2016
Kind
B2
Abstract

A secure active network includes a plurality of secure elements which communicate with one another to share and log information such as identification, location, and user activity associated with each secure element. Secure elements exchange data with one another, and log data received. The periodicity of communication between secure elements, encryption of the information, and the operating frequency in which the information is transmitted and received may be changed if communication is lost between any of the secure elements or if a determination is made that a secure element has traveled outside a predetermined zone. The integrity of the secure network may be verified at any time by comparing the logged information to a reference network.

Claims (55)

1. A secure network element, comprising:

a communications module configured to receive location data, indicating a location of a second secure network element, according to a first communications protocol at scheduled communication sessions; and

a processor configured to:

compare the location data to a reference location data range at the scheduled communication sessions,

change an encryption in response to determining that the location data deviates from the reference location data range, and

change the first communications protocol to a second communications protocol in response to determining that communications have been lost between the secure network element and the second secure network element.

2. The secure network element of claim 1 , wherein the communications module is further configured to attempt to exchange data with the second secure network element, the data being indicative of an identification of the secure network element and the second secure network element, according to the first communications protocol.

3. The secure network element of claim 2 , wherein the processor is further configured to change the first communications protocol to the second communications protocol if a number of failed data exchanges exceeds a threshold number.

4. The secure network element of claim 1 , wherein the communications module is further configured to:

encrypt data sent to the second secure network element in accordance with a first encryption as part of the first communications protocol, and

encrypt data sent to the second secure network in accordance with a second encryption as part of the second communications protocol.

5. The secure network element of claim 1 , wherein the first communications protocol includes wireless communication according to a first frequency, and wherein the second communications protocol includes wireless communication according to a second frequency.

6. The secure network element of claim 2 , further comprising:

a memory configured to store data received from the second secure network element as logged data, wherein the logged data includes a timestamp corresponding to each of the communication sessions and an indication of whether data was received from the second secure network element.

7. The secure network element of claim 2 , wherein the secure network element is coupled to a device, the secure network element further comprising:

a memory for storing an encrypted serial number of the device as the identification of the secure network element.

8. In a secure network element, a method comprising:

attempting to exchange location data with a second secure network element according to a communication protocol;

determining expected location data for the second secure network element;

generating a data log based on the location data, the data log comprising:

a plurality of timestamps corresponding to the communications protocol, and

a plurality of indications, for respective timestamps in the plurality of timestamps, regarding whether the data was received from the second secure network element;

changing an encryption key in response to determining, based on the location data log, that the location data from the second secure network element deviates from the expected location data; and

changing the communication protocol in response to determining that communications have been lost between the secure network element and the second secure network element.

9. The method of claim 8 , further comprising:

changing the communication protocol if the location data received from the second secure network element indicates that the second secure network element traveled outside a predetermined zone.

10. The method of claim 8 , further comprising:

sending a data flag to the second secure network element if the data log indicates that a total number of instances the data was not received is above a threshold number.

11. The method of claim 8 , further comprising:

changing the communications protocol upon receipt of a data flag sent by the second secure network element.

12. A method for dynamic network operation, the method comprising:

determining a communication partner of a secure network element that is within a communication range of the secure network element;

determining expected location data for the communication partner;

creating a data log based on location data exchanged with the communication partner;

changing an encryption key in response to determining, based or the data log, that the location data from the communication partner deviates from the expected location data; and

changing a communication protocol in response to determining, based on the data log, that communications have been lost between the secure network element and the communication partner.

13. The method of claim 12 , further comprising:

monitoring data flags received from the communication partner.

14. The method of claim 12 , further comprising:

receiving a data flag from the communication partner; and

determining a type of communication anomaly based on the data flag.

15. The method of claim 12 , further comprising:

retrieving communication profile settings corresponding to the data flag in response to determining that a data flag was received from the communication partner.

16. The method of claim 12 , further comprising:

setting a low priority data flag in response to determining that communications have been lost between the secure network element and the communication partner; and

setting a high priority data flag in response to determining that the location data from the communication partner deviates from the expected location data.

17. The method of claim 12 , further comprising:

determining whether a number of communication errors received from the network partner exceeds a threshold number of errors in a reference network signature of the communication partner.

18. The method of claim 12 , further comprising:

determining, based on a comparison between the data log and an expected data log, whether the communication partner has been compromised.

19. The method of claim 12 , wherein the data log further comprises expected location data for a plurality of communication partners, and wherein the method further comprises:

generating a reconstructed network of the plurality of communication partners based on the data log.

20. The method of claim 19 , further comprising:

comparing the reconstructed network with reference network signatures of the plurality of communication partners; and

determining, based on comparing the reconstructed network with the reference network signatures, whether the plurality of communication partners comprises an anomalous communication partner.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Feb 3, 2017
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 041712/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 1, 2016
From: BROADCOM CORPORATION
To: NXP B.V.
Reel/Frame 039901/0237 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Aug 10, 2016
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: BROADCOM CORPORATION
Reel/Frame 039646/0092 →
PATENT SECURITY AGREEMENT Recorded Feb 11, 2016
From: BROADCOM CORPORATION
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 037806/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 20, 2012
From: MARKEL, SHLOMO; MENDEL, JACOB
To: BROADCOM CORPORATION
Reel/Frame 029514/0242 →